CVE-2024-31903
HIGH 8.8EPSS 1.0%
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.97% chance of exploitation in the next 30 days, 59th percentile
- Published
- 2025-01-22
- Updated
- 2025-02-12
Proof-of-concept exploits (2)
- ReversecLabs/ibm-sterling-b2b-integrator-poc1★ · 2025-02-18
- WithSecureLabs/ibm-sterling-b2b-integrator-poc1★ · 2025-02-18